Description
A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-01-28: | Advisory disclosed |
| 2026-01-28: | VulDB entry created |
| 2026-02-09: | VulDB entry last update |
Credits
hackerfactory (VulDB User)
References
vuldb.com/?id.343246 (VDB-343246 | PHPGurukul Hospital Management System Admin Dashboard adminviews.py improper authorization)
vuldb.com/?ctiid.343246 (VDB-343246 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.739837 (Submit #739837 | PHPGurukul Hospital Management System v1.0 Missing Authorization)
github.com/...ment-System/blob/main/Broken Access Control.md
phpgurukul.com/